→ All assistants
Zayenha Cybersecurity
AI assistant for cybersecurity and data protection officers
This assistant is available to Pro subscribers
You can browse the knowledge base and prompts here. To use the interactive assistant, upgrade to Pro.
Upgrade to Pro to use the assistant →
The Zayenha Cybersecurity assistant supports every aspect of cybersecurity governance and regulatory compliance in the Saudi context: drafting data classification policies and incident-response plans aligned with the Essential Cybersecurity Controls (ECC-2:2024) and the Personal Data Protection Law (PDPL), building risk assessments and control mappings against NIST CSF, OWASP, and MITRE ATT&CK, and turning security-assessment findings into clear executive reports. Built for CISOs, GRC teams, and compliance officers who need precise, source-backed, immediately usable output.
Example tasks it handles
Example 1
Draft an internal data classification policy aligned with DCC-1:2022 and NCA's four ECC domains
Example 2
Prepare a data-breach incident-response plan that meets the Personal Data Protection Law's notification requirements
Example 3
Build a NIST CSF 2.0 gap-assessment report with a phased remediation plan
Example 4
Turn penetration-test findings into an executive report mapped to MITRE ATT&CK tactics
Knowledge base reference
Reference material the assistant draws on. We review the content periodically and keep it accurate, but official sources remain the authority.
Best Practices
MITRE ATT&CK Framework
+
MITRE ATT&CK is a globally recognized, open knowledge base developed by the U.S. non-profit MITRE Corporation (internal work began in 2013, publicly released in 2015), documenting real adversary tactics, techniques, and procedures (TTPs) observed in actual attacks, not theoretical ones. Security Operations Centers (SOCs) and incident-response teams rely on it for three core uses: building precise detection use-cases, conducting adversary emulation to actually test defenses, and assessing defensive coverage gaps against a globally recognized tactics matrix. When drafting an incident-response playbook or threat-analysis report for a Saudi organization, citing a specific ATT&CK technique ID measurably raises the output's professional rigor.
NIST Cybersecurity Framework (CSF) 2.0
+
NIST released version 2.0 of its Cybersecurity Framework on 26 February 2024, the first major update since the 2014 edition. Its headline addition is a sixth, central function called "Govern," which directs and connects the other five functions — Identify, Protect, Detect, Respond, and Recover — rather than leaving them disconnected from governance decisions. The new version also expands the framework's applicability to organizations of any size or sector, not just critical infrastructure as before. An excellent reference for building a gap assessment that covers governance, not only technical controls.
ISO/IEC 27001:2022 Information Security Management
+
The updated ISO/IEC 27001 standard fully restructured Annex A: from 114 controls in the 2013 edition down to 93 controls across just four themes — organizational (37), people (8), physical (14), and technological (34). The new edition adds 11 entirely new controls reflecting present-day threats, most notably threat intelligence (5.7), information security for cloud services (5.23), and data leakage prevention (8.12). When building an Information Security Management System (ISMS) for a Saudi organization pursuing both international certification and local ECC compliance, use this four-theme structure as the backbone of the internal policy set.
Regulations & Laws
Essential Cybersecurity Controls (ECC-2:2024)
+
The National Cybersecurity Authority (NCA) issued the updated Essential Cybersecurity Controls ECC-2:2024, replacing the first edition ECC-1:2018 which held 114 controls across five domains. The new edition restructures the framework around just four main domains: Cybersecurity Governance, Cybersecurity Defense, Cybersecurity Resilience, and Third-Party & Cloud Computing Cybersecurity — folding what was once a standalone fifth domain into the four. When drafting a compliance policy or plan for a Saudi entity, always start by identifying which of these four domains the document addresses, since that is the classification NCA itself uses in its official reviews.
Data Cybersecurity Controls (DCC-1:2022)
+
The NCA issued the Data Cybersecurity Controls (DCC-1:2022) on 1 November 2022 to set minimum requirements for protecting data across its entire lifecycle — from creation and storage through processing and sharing to secure disposal. The controls are mandatory for government entities and private-sector organizations operating critical national infrastructure, and define a four-tier data classification system by sensitivity, with the top tier (top secret) requiring strict access controls, documented disposal procedures, and regular audits. When drafting an internal data classification policy for a Saudi organization, treat these four tiers as a mandatory reference framework, not an optional one.
Cloud Cybersecurity Controls (CCC-1:2020)
+
The NCA designed the Cloud Cybersecurity Controls (CCC-1:2020) to minimize risk on both sides of the cloud relationship: Cloud Service Providers (CSPs), covered by 37 main domains / 96 sub-domains, and Cloud Service Tenants (CSTs), covered by 18 main domains / 26 sub-domains, all within four unified core components. NCA also mapped these controls against internationally recognized standards — US FedRAMP, Singapore's MTCS, Germany's C5, ISO/IEC 27001, and the CSA Cloud Controls Matrix — making it easier for a Saudi organization working with a global cloud provider to demonstrate dual compliance without duplicating documentation effort.
PDPL Penalties and Fines
+
The Saudi PDPL sets two distinct penalty tracks depending on the violation. Article 35 imposes a criminal penalty of up to two years' imprisonment and/or a SAR 3 million fine, specifically for disclosing sensitive personal data with intent to harm the data subject or for personal gain. Article 36 sets an administrative penalty (a warning or a fine of up to SAR 5 million) for all other violations of the law. In both tracks, fines can be doubled for repeat offenses — making documented processing controls and data-subject consent records the first line of defense before a penalty is even on the table.
Personal Data Protection Law (PDPL) — Effective Date & Competent Authority
+
Saudi Arabia's PDPL was issued by Royal Decree No. M/19 dated 9/2/1443H (2021), with Article 43 stipulating it takes effect 720 days after publication in the Official Gazette — i.e., 14 September 2023 — with a further compliance grace period for organizations ending 14 September 2024. SDAIA is the competent authority overseeing implementation, while Article 30 preserves the Saudi Central Bank's (SAMA) powers under its own regulations without prejudice to the PDPL. The law was later amended by Royal Decree No. M/148 dated 5/9/1444H, and its Implementing Regulation was approved via SDAIA President's Administrative Decision No. 1516/1445H.
Anti-Cyber Crime Law
+
Saudi Arabia's Anti-Cyber Crime Law was issued by Royal Decree No. M/17 dated 8/3/1428H (26 March 2007), alongside Council of Ministers Resolution No. 79 issued one day earlier, following the usual sequence between cabinet approval and decree issuance. The law explicitly criminalizes acts such as unauthorized access to information systems, website hacking, data theft, and electronic fraud, and prescribes penalties including imprisonment and fines alongside confiscation of devices and tools used in the offense. This is the oldest and broadest criminal reference to invoke when drafting any incident-response policy involving a breach or unauthorized access in the Saudi context — typically cited alongside, not instead of, the PDPL.
Ready Templates
SAMA Cybersecurity Framework Self-Assessment Template
+
SAMA's Cybersecurity Framework (issued May 2017) requires every regulated financial institution to complete a SAMA-prepared self-assessment questionnaire that scores cybersecurity maturity on a 6-level scale (0 to 5), with reaching at least level 3 mandated as a floor, not merely a recommended target. SAMA periodically reviews these self-assessment results to determine an institution's actual compliance and maturity level, and any gap below level 3 requires a documented remediation plan with a clear timeline. This template is the essential reference when preparing any cybersecurity maturity report for a Saudi financial entity.
Ready prompts in this field
Human-vetted, ready-to-use prompts.
OWASP Top 10 Code Security Audit with Fixes
Audit code against OWASP Top 10 (2021), rank findings by severity, and deliver a complete fix for each confirmed vulnerability without false…
pro
Use →
Personal Data Protection (PDPL) Compliance Program
For privacy officers and counsel: a compliance program for the Saudi Personal Data Protection Law covering records of processing, lawful bas…
pro
Use →
Data Localization & Cross-Border Transfer Compliance Framework (PDPL Article 29, SCCs)
Draft a comprehensive data localization and cross-border transfer compliance framework under PDPL Article 29 and Standard Contractual Clause…
pro
Use →
Corporate Regulatory Compliance Program with Obligations Matrix
For compliance officers and counsel: a corporate regulatory compliance program that maps obligations, assigns owners, and defines controls, …
plus
Use →
Risk Analysis Matrix from Identification to Response Plan
Turn project risks into a matrix ranked by likelihood and impact with a response plan for each, for project and risk managers, without fabri…
pro
Use →
Enterprise Risk Assessment with Register and Response Plan
For risk managers and executives: a systematic enterprise risk assessment that builds a register classified by likelihood and impact, with a…
plus
Use →
GitHub Actions CI/CD Review
Review a GitHub Actions workflow across 10 dimensions (security, secrets, caching, concurrency, OIDC) with an optimized runnable version.
plus
Use →
Kubernetes Manifests Review
Review Deployment + Service + Ingress + ConfigMap across 12 dimensions (probes, resources, PodSecurity, NetworkPolicy) with corrected manife…
pro
Use →
Terraform Module Review
Review a Terraform module across 10 dimensions (state, providers, variables, outputs, composition, security) with actionable fixes.
plus
Use →
Dockerfile Multi-stage Build Review
Review a Dockerfile across 10 dimensions (multi-stage, cache layers, image size, security, non-root user) with a buildable optimized version…
plus
Use →
Regulatory Compliance Checklist for a Saudi Business
For compliance officers and owners needing a structured checklist covering licensing, labor, zakat and tax, and data protection, marking the…
pro
Use →
Initial Incident Response Plan for a Data Breach
Helps security and incident-response teams prepare an initial (first 72-hour) response plan for a data breach: containment, evidence, regula…
pro
Use →
Start now, boost your productivity
First prompt is free. No credit card required.
Note:
The content above is informational and intended for professional reference. It is not formal legal, tax, or professional advice. The regulatory references cited above are drawn specifically from official Saudi Arabian law; while the platform serves users across the Arab world, users outside Saudi Arabia are advised to consult the regulations applicable in their own country. Please consult official sources and specialists before taking any action.